Trusted Execution Environment Abnormality Detection via Encrypted Debugging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for tracking and locating issues in a trusted execution environment (TEE) of terminal devices are inefficient and inaccurate, especially when multiple applications are involved, leading to poor problem-solving efficiency and accuracy.

Innovation Solution

A method that involves acquiring the running state of a target application in the TEE, determining abnormality, generating and encrypting debugging information and keys, and sending them to a server for abnormality detection, using a secure channel to ensure security and accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual tracking and location of problems in TEE is performed by personnel, then data security is maintained, but efficiency and accuracy of problem tracking deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidefficiency of problem tracking
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables automatic self-monitoring and self-reporting of abnormal conditions within the TEE. The abnormal condition detection module automatically detects anomalies, generates debugging information, encrypts it, and transmits it to the server without requiring manual intervention from personnel, thereby improving efficiency while maintaining security through automated processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes a feedback loop where the TEE automatically monitors its own running state, detects abnormalities, and reports them to the server. This continuous feedback mechanism enables real-time monitoring and rapid response to security issues without manual tracking, resolving the contradiction between automated monitoring and manual security oversight

Inventive Principle:
Principle #23Feedback

2Reliability

If manual tracking and location of problems in TEE is performed by personnel, then data security is maintained, but accuracy of problem location deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidaccuracy of problem location
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent replaces manual mechanical tracking methods with automated electronic systems. The abnormal condition detection module uses computer-based detection mechanisms to identify and locate problems within the TEE, generating precise debugging information that includes temporal and contextual data for accurate problem location without human intervention

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system creates digital copies of the TEE's running state and debugging information. By generating and transmitting encrypted copies of diagnostic data to the server, the system enables precise reproduction and analysis of abnormal conditions without exposing the actual TEE environment, thereby maintaining security while improving location accuracy

Inventive Principle:
Principle #26Copying

3Speed

If debugging information is transmitted without encryption, then transmission speed is improved, but data security deteriorates

Engineering Contradiction:
Improvetransmission speedVSAvoiddata security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary encryption of debugging information before transmission. The encryption module encrypts the debugging information generated by the TEE using secure algorithms, preparing it for safe transmission to the server. This preliminary security measure ensures that data is protected from the outset without significantly impacting transmission speed

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces encryption as an intermediary layer between the TEE and the server. The encryption module acts as a mediator that transforms the debugging information into an encrypted format for transmission, maintaining security while allowing the transmission process to proceed efficiently through standard communication channels

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230409718A1Data processing methods, apparatuses, and devices
Publication Date: 2023.12.21 ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
  • US20230409718A1 patent drawing
  • US20230409718A1 patent drawing
  • US20230409718A1 patent drawing

AI summary

Some embodiments of this specification provide data processing methods, apparatuses, and devices. One method includes: receiving encrypted debugging information and an encrypted first key from a client device, determining the device key corresponding to the client device, obtaining the debugging information based on the device key, the encrypted debugging information, and the encrypted first key, and performing abnormality detection on the trusted execution environment of the client device based on the debugging information to determine an abnormality detection result for the trusted execution environment.